Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-91939

3 дня назад

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-91939

3 дня назад

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv9c-9hwm-jp8g

3 дня назад

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-91939

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

CVSS3: 9.8
1%
Низкий
3 дня назад
debian логотип
CVE-2026-91939

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unseriali ...

CVSS3: 9.8
1%
Низкий
3 дня назад
github логотип
GHSA-xv9c-9hwm-jp8g

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.

CVSS3: 9.8
1%
Низкий
3 дня назад

Уязвимостей на страницу